BigHugger
sk Skill · mukul975

analyzing-slack-space-and-file-system-artifacts

Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
usn-journalbashmftfile-system-analysisalternate-data-streamsntfsslack-spacePythonforensics
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python